Repository navigation
chore: bump pinned CodeQL CLI to v2.27.2 and release v0.8.2 - #236
security-lab-bot[bot] wants to merge 2 commits into
Conversation
|
@copilot 2.27.2 has some breaking changes - is this why our ci is failing? https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/actions/runs/37988104873/job/114028147745?pr=236 Please fix Breaking Changes¶ BasicBlocks::Cfg has been removed. BasicBlock now directly uses the basic-block implementation provided by the shared CFG library. ControlFlow::EntryNode and ControlFlow::ExitNode have been added, and ControlFlow::entryNode and ControlFlow::exitNode now return these more specific types. IfStmt.getCond has been deprecated. Please use the new IfStmt.getCondition instead. The result types of IfStmt.getThen and LoopStmt.getBody have been widened from BlockStmt to Stmt. SwitchStmt.getExpr has been added, providing a common accessor for the expression examined by expression and type switches. Several IR instruction classes have been removed or consolidated, including ReadArgumentInstruction, InitResultInstruction, IncDecInstruction, EvalIncDecRhsInstruction, EvalImplicitOneInstruction, SelectInstruction, and SendInstruction. EvalCompoundAssignRhsInstruction now also represents increment and decrement operations, and it and EvalImplicitInitInstruction directly represent their associated writes. |
Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>
Yes, the CodeQL 2.27.2 Go CFG rewrite changed internal provenance IDs, not the detected source-to-sink path. I updated the test expectation; all 3 Go tests pass. Commit: |
Automated CLI version bump, requested via the "Update CodeQL CLI Version"
workflow (
workflow_dispatch,codeql_version: 2.27.2,release_bump: patch).This PR:
Updates
.codeqlversionto2.27.2.Pins every
codeql/<lang>-all/codeql/<lang>-queriesdependencies:entry across query/library
qlpack.ymlfiles (not*/extor*/ext-library-sources, whoseextensionTargetsis intentionally leftunconstrained and must never be auto-rewritten) to the exact version
shipped in the official CodeQL Bundle for this CLI release (see
.github/scripts/pin-codeql-library-versions.sh) - this keepscodeql pack upgradefrom jumping those libraries to registry-latest insteadof the version this CLI actually ships/tests against.
Runs
codeql pack upgrade <dir>for every query/library pack directory (againexcluding
*/extand*/ext-library-sources) to refresh itscodeql-pack.lock.ymlagainst the new CLI and pinned library versions.Also bumps the repo release version (
patch, via the samepatch-release-mestepupdate-release.ymluses) to0.8.2,propagating it to every pack's own
version:field,configs/*.ymlreferences, and cross-pack
-libspins.Merging this PR triggers the real batch publish -
publish.yml'sauto-trigger fires on any push to
mainthat changes.release.yml, which thisPR does. No separate "CodeQL Update Release" run is needed. That run's
summaryjob will create the matching GitHub Release as a full release
(
release_prerelease: false).Remaining steps (see CONTRIBUTING.md's "Updating the pinned CodeQL CLI/library
version" section):
API changes. This is usually the hardest part; consider delegating it to a
Copilot coding agent session pointed at this PR/branch.